Stuxnet virus could target many industries
November 17, 2010 By LOLITA C. BALDOR , Associated Press
(AP) -- A malicious computer attack that appears to target Iran's nuclear plants can be modified to wreak havoc on industrial control systems around the world, and represents the most dire cyberthreat known to industry, government officials and experts said Wednesday.
They warned that industries are becoming increasingly vulnerable to the so-called Stuxnet worm as they merge networks and computer systems to increase efficiency. The growing danger, said lawmakers, makes it imperative that Congress move on legislation that would expand government controls and set requirements to make systems safer.
The complex code is not only able to infiltrate and take over systems that control manufacturing and other critical operations, but it has even more sophisticated abilities to silently steal sensitive intellectual property data, experts said.
Dean Turner, director of the Global Intelligence Network at Symantec Corp., told the Senate Homeland Security and Governmental Affairs Committee that the "real-world implications of Stuxnet are beyond any threat we have seen in the past."
Analysts and government officials told the senators they remain unable to determine who launched the attack. But the design and performance of the code, and that the bulk of the attacks were in Iran, have fueled speculation that it targeted Iranian nuclear facilities.
Turner said there were 44,000 unique Stuxnet computer infections worldwide through last week, and 1,600 in the United States. Sixty percent of the infections were in Iran, including several employees' laptops at the Bushehr nuclear plant.
Iran has said it believes Stuxnet is part of a Western plot to sabotage its nuclear program, but experts see few signs of major damage at Iranian facilities.
A senior government official warned Wednesday that attackers can use information made public about the Stuxnet worm to develop variations targeting other industries, affecting the production of everything from chemicals to baby formula.
"This code can automatically enter a system, steal the formula for the product you are manufacturing, alter the ingredients being mixed in your product and indicate to the operator and your antivirus software that everything is functioning as expected," said Sean McGurk, acting director of Homeland Security's national cybersecurity operations center.
Stuxnet specifically targets businesses that use Windows operating software and a control system designed by Siemens AG. That combination, said McGurk, is used in many critical sectors, from automobile assembly to mixing products such as chemicals.
Turner added that the code's highly sophisticated structure and techniques also could mean that it is a one-in-a-decade occurrence. The virus is so complex and costly to develop "that a select few attackers would be capable of producing a similar threat," he said.
Experts said governments and industries can do much more to protect critical systems.
Michael Assante, who heads the newly created, not-for-profit National Board of Information Security Examiners, told lawmakers that control systems need to be walled off from other networks to make it harder for hackers to access them. And he encouraged senators to beef up government authorities and consider placing performance requirements and other standards on the industry to curtail unsafe practices and make systems more secure.
"We can no longer ignore known system weaknesses and simply accept current system limitations," he said. "We must admit that our current security strategies are too disjointed and are often, in unintended ways, working against our efforts to address" cybersecurity challenges.
The panel chairman, Sen. Joe Lieberman, I-Conn., said legislation on the matter will be a top priority after lawmakers return in January.
More information: Senate Homeland Security and Governmental Affairs Committee: http://hsgac.senate.gov/public/
©2010 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.
-
From lemons to lemonade: Reaction uses carbon dioxide to make carbon-based semiconductor,
28 comments
-
Every black hole contains a new universe: A physicist presents a solution to present-day cosmic mysteries,
217 comments
-
New silicon memory chip developed,
16 comments
-
Thioridazine kills cancer stem cells in human while avoiding toxic side-effects of conventional cancer treatments,
3 comments
-
SpaceX private rocket blasts off for space station (Update),
41 comments
-
length of wire in a coil of known dimensions?
10 hours ago
-
India Engineering Powerhouse
17 hours ago
-
electromagnet core dereference between hard and soft iron
18 hours ago
-
Measuring water pressure in an open tank
May 24, 2012
-
Question from a non-engineer: Pulley Systems
May 24, 2012
-
Formula to calculate psi required to deliver gpm through nozzel
May 23, 2012
- More from Physics Forums - General Engineering
More news stories
Yahoo kills 'Livestand' just 6 months after debut
(AP) -- Yahoo is killing a tablet magazine called Livestand just six months its debut on the iPad.
5 hours ago |
not rated yet |
1
Computers excel at identifying smiles of frustration (w/ Video)
(Phys.org) -- Researchers at the Massachusetts Institute of Technology (MIT) in the US have trained computers to recognize smiles, and they have turned out to be more adept at recognizing smiles of frustration ...
Yahoo! ditches digital newsstand for iPads
Yahoo! shuttered its fledgling digital newsstand for iPads on Friday in what it said was the start of a product purge intended to make the floundering Internet pioneer more nimble.
6 hours ago |
not rated yet |
0
Facebook IPO debacle raises investor dander
The spate of complaints and investigations over the Facebook stock offering suggests big institutions had an edge over small investors, raising questions about the process.
7 hours ago |
not rated yet |
0
Apple CEO Cook gives up $75M in stock dividends
(AP) -- Apple CEO Tim Cook is giving up $75 million in dividends on restricted stock that the company is awarding to all of its employees.
11 hours ago |
1.8 / 5 (4) |
2
Of mice and mental models: Neuroscientific implications of risk-optimized behavior in the mouse
(Medical Xpress) -- Regardless of an organism’s biological complexity, every encephalized animal continuously makes under-informed behavioral choices that can have serious consequences. Despite its ubiquity, ...
Dragon arrives at space station in historic 1st (Update 2)
The privately bankrolled Dragon capsule made a historic arrival at the International Space Station on Friday, triumphantly captured by astronauts wielding a giant robot arm.
Landmark calculation clears the way to answering how matter is formed
(Phys.org) -- An international collaboration of scientists, including Thomas Blum, associate professor of physics, is reporting in landmark detail the decay process of a subatomic particle called a kaon ...
High-speed method to aid search for solar energy storage catalysts
Eons ago, nature solved the problem of converting solar energy to fuels by inventing the process of photosynthesis.
It's in the genes: Research pinpoints how plants know when to flower
Scientists believe they've pinpointed the last crucial piece of the 80-year-old puzzle of how plants "know" when to flower.
Researchers solve structure of human protein critical for silencing genes
In a study published in the journal Cell on May 24, Cold Spring Harbor Laboratory (CSHL) scientists describe the three-dimensional atomic structure of a human protein bound to a piece of RNA that "guides" the pr ...
Nov 17, 2010
Rank: 3 / 5 (4)
Nov 17, 2010
Rank: 3.3 / 5 (3)
Nov 17, 2010
Rank: not rated yet
Nov 17, 2010
Rank: 2.3 / 5 (3)
I've worked in IT security for 10 years. Your statement shows the depth of your ignorance. Its not a question of security, its a question of "securable". On that note: Windows is not securable, Linux can be made 100% securable.
Nov 17, 2010
Rank: 3.7 / 5 (3)
The reason Linux (and MacOS) are rarely attacked is because there are far fewer of them than WindowOS in public use. There are not only HUGE vulnerabilities of the internet itself that no OS can overcome, but no system is 100% secure as long as you allow people to access it.
10 years is not a lot in terms of real experience btw.
Nov 18, 2010
Rank: not rated yet
Nov 18, 2010
Rank: 4 / 5 (2)
With 5 times as much IT experience under my belt, I can tell you, without fear of being in error, that there is no such thing as being both 100% secure and usable.
Usability requires accessibility; which, in turn, allows of unauthorized access.
BTW, Unix-like OSes are actually more easily controlled, for good or for bad, than is Windows, owing to their granularity; it is for that reason that they are vulnerable to root kits. Windows, on the other hand, has no true root, thus requiring a multi-vector attack in order to effect the equivalent level of control afforded by a true root kit.